Description
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Remediation
References
http://www.securityfocus.com/bid/94221
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2019-17267 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-42357 Vulnerability in maven package org.apache.knox:gateway-service-knoxsso
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2019-6286 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-43484 Vulnerability in maven package org.terasoluna.gfw:terasoluna-gfw-common